Guides

WordPress Hacked? The 7-Step Recovery Protocol (2026)

By Editorial TeamSeptember 18, 20262 min read

Quick answer: Hacked WordPress recovery in 7 steps: isolate the site, scan to confirm, clean or restore from a pre-infection backup, rotate every credential, reinstall core, request Google review, then harden so it doesn't happen again. Act within hours — Google blacklists fast.

Step 1-2: Isolate and Confirm

Take the site offline or into maintenance mode — a live hacked site spreads malware to visitors and gets blacklisted. Then confirm the infection: run a Wordfence scan, check for unknown admin users, look for recently modified files you didn't touch, and check Search Console's Security Issues report. Document what you find — you'll need it for cleanup.

Step 3: Clean — Two Paths

PathWhenRisk
Restore clean backupBackup predates infectionLose recent content; backup may be infected too
Manual cleanupNo clean backup existsMiss one backdoor, reinfected in days

Manual cleanup means: reinstall WordPress core from wordpress.org (fresh wp-admin, wp-includes), replace plugins/themes with fresh copies from official sources, scan uploads for injected PHP, and audit the database for malicious posts and admin users. Miss one backdoor and you're reinfected within days — when in doubt, professional cleanup ($100-300) beats a second hack.

Step 4-5: Rotate Everything, Reinstall Core

Every credential changes: hosting panel, wp-admin (all users), database, FTP/SFTP, API keys, and your WordPress salts in wp-config.php (invalidates all sessions). Do it from a device you've scanned — if your laptop has the keylogger, new passwords don't help.

Step 6-7: Google Review and Hardening

Clean first, then request review in Search Console — Google re-scans in 24-72 hours. Then close the entry point: enable auto-updates, set up two-factor authentication, install a security plugin, and work through our 15-step security checklist. If the hack came through a vulnerable plugin or theme, check whether your page builder or an abandoned plugin was the vector.

Hosting That Helps Prevent This

Bluehost includes malware scanning, free SSL, and account isolation — plus free migration if your current host was the weak link.

Get Bluehost from $2.95/mo →
Find Your Perfect Hosting Plan

What are you building?

Tell us about your project so we can match the perfect hosting plan.

Question 1 of 425% complete
Interactive Tool

Hosting Cost Calculator

See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.

Used to calculate transaction fees (Shopify charges 2% on sales)

Shopify Basic (3yr)
$1,044
Bluehost (3yr)
$444
You Save
$600
58% less than Shopify Basic

Frequently Asked Questions

What should I do first if my WordPress site is hacked?

Isolate it — put the site in maintenance mode or take it offline, then change all passwords (hosting, wp-admin, database, FTP) from a clean device. Speed matters: malware spreads and Google blacklists within hours.

How do I know if my WordPress site is hacked?

Common signs: Google 'This site may be hacked' warnings, sudden traffic drops, unknown admin users, redirected visitors, strange files or code injections, hosting suspension notices, and outbound spam emails from your server.

Can I clean a hacked WordPress site myself?

Yes if you're technical — restore from a clean backup, or manually remove malicious files after a Wordfence/Sucuri scan, reinstall core from wordpress.org, and rotate every credential. If the hack persists or you're unsure, professional cleanup (~$100-300) is worth it.

Will restoring a backup remove the hack?

Only if the backup predates the infection — malware often sits dormant for weeks. Scan the backup before restoring, and still rotate all credentials afterward since the entry point (usually a stolen password or vulnerable plugin) remains open otherwise.

How do I remove a Google blacklist warning?

Clean the site completely first, then request a review in Google Search Console (Security Issues report). Google typically re-scans within 24-72 hours. Requesting review before cleaning just delays removal.

How do I prevent getting hacked again?

Find the entry point first — check for vulnerable plugins, weak passwords, or missing 2FA. Then: auto-updates on, 2FA on all admin accounts, a security plugin, off-server backups, and a host with account isolation. Our security checklist covers all 15 steps.

Ready to launch?

Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.

Start for $3.99

Related Articles